Self-hosted assets
The public site should be inspectable from its own build output.
Fonts, images, CSS, JavaScript, icons, and other interface assets should ship from the site unless there is a specific reason to depend on a remote runtime service.
Rule#
Self-host assets by default. A remote asset is an exception that needs a reason, a disclosure decision, and a maintenance owner.
Applies to#
- web fonts
- JavaScript libraries
- CSS frameworks or generated CSS
- icons and interface images
- downloaded product images when licensing allows local hosting
- generated files such as search indexes, feeds, and machine-readable surfaces
Why#
Self-hosting keeps the site:
- faster to render
- easier to archive
- easier to test
- less dependent on third-party uptime
- less exposed to third-party tracking
- clearer about what code runs in the browser
Exceptions#
A remote dependency may be acceptable when it is the product being demonstrated, a legally required source, a live service that cannot be represented locally, or a temporary migration state.
Document the exception near the feature and disclose it where a visitor or maintainer would reasonably expect to find it.
Maintenance#
When adding an asset, answer three questions:
- Where is the local source?
- What license or permission allows use?
- Does this asset cause browser-side requests outside the site?